Businesses brace for second 'Fujiwhara effect' of 2020 as Patch Tuesday looms

Organisations set for a day of chaos on 14 April as vendors plan to fix 500-plus software vulnerabilities at once

Software giants will release fixes for hundreds of bugs in unison for the second time this year, at a time when IT teams are already under pressure from mass adoption of remote working and surging cyber crime.

The forthcoming Patch Tuesday, on 14 April, will see as many as 500 vulnerabilities released by the likes of Microsoft and Oracle, causing a phenomenon dubbed the ‘Fujiwhara effect’. Such a security event is ordinarily rare, with the last one before 2020 occurring in 2014. 

Advertisement - Article continues below

This year has been no stranger to coordinated bug fixes, with next Tuesday representing the second ‘Fujiwhara effect’ in 2020, according to Risk Based Security. This is in addition to a third event scheduled to hit on 14 July.

Such coordination of bug fixes poses a challenge for security teams, who must analyse and prioritise hundreds of disclosures before remediation can even begin.

This coming Tuesday may see as many as 300 to 500-plus fixes released, according to forecasts. This is significantly higher than average, with roughly 60 flaws published per day, normally.

This latest onslaught will also come at a time when employees have begun working from home en masse, and cyber criminals have been empowered by the COVID-19 pandemic to ramp up activity significantly.

Advertisement
Advertisement - Article continues below

“Even for large organizations, processing these new “Patch Tuesday” disclosures can take weeks, and that’s with a well-funded and coordinated team,” said Risk Based Security. “The hours required for IT security teams to collect, analyze, triage, and then address the coming vulnerabilities will be considerable.

Advertisement - Article continues below

“If there wasn’t enough going on already, organizations must somehow manage the coming Vulnerability Fujiwhara Effect despite the current business disruption and pressure on security budgets.”

The ‘Fujiwhara effect’ in meteorology is known as an extreme weather event in which two massive hurricanes collide or merge.

The last cyber security ‘Fujiwhara effect’ on 14 January, saw more than ten major software players participate, including Adobe, SAP, Schneider Electric, VMWare, Intel, as well as Oracle and Microsoft, among others.

The release of so many patches at once, numbering more than 300, saw IT and security teams across the world scramble to implement updates to their business-critical systems.

Among these fixes was a Microsoft-developed patch for an "extraordinarily serious" cryptographic flaw anchored in the crypt32.dll Windows component, with organisations like the US military given advanced access to the fix.

Winding forward some months, organisations are facing greater challenges than arguably ever before, in terms of the economy and the labour market, not to mention cyber security threats increasing significantly over the last few weeks. 

The UK’s National Cyber Security Centre (NCSC) this week issued a joint-warning with US cyber security authorities warning businesses of a surge in cyber criminal activity, most of which was attempting to exploit the coronavirus pandemic.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/security/encryption/355820/k2view-innovates-in-data-management-with-new-encryption-patent
encryption

K2View innovates in data management with new encryption patent

28 May 2020
Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020
Visit/security/hacking/355382/whatsapps-flaw-shoulder-surfing
hacking

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
Visit/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020

Most Popular

Visit/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020
Microsoft Windows

Microsoft warns users not to install Windows 10's May update

28 May 2020
Visit/security/data-breaches/355777/easyjet-faces-class-action-lawsuit-over-data-breach
data breaches

EasyJet faces class-action lawsuit over data breach

26 May 2020
Visit/security/cyber-security/355797/microsoft-bans-trend-micros-rootkit-buster-from-windows-10
cyber security

Microsoft bans Trend Micro driver from Windows 10 for "cheating" hardware tests

27 May 2020